logo
Azul boosts Java security with improved runtime vulnerability detection

Azul boosts Java security with improved runtime vulnerability detection

Techday NZ13-06-2025

Azul has introduced enhanced vulnerability detection capabilities to its Intelligence Cloud that aim to reduce false positives and improve the accuracy of identifying Java application security risks.
The company's updated solution, called Azul Vulnerability Detection, now uses class-level production runtime data to detect known vulnerabilities within Java applications. This approach contrasts with conventional application security (AppSec) and application performance monitoring (APM) tools, which often flag vulnerabilities based on component file names or software bill of materials (SBOM) data. Such traditional practices can generate a large volume of false positives, which the company asserts unnecessarily divert DevOps teams' time and effort.
Based on findings from the Azul 2025 State of Java Survey & Report, a significant proportion of organisations are affected by this problem, with 33% indicating that more than half of their DevOps teams' time is spent addressing false positives related to Java Common Vulnerabilities and Exposures (CVEs) alerts. The broad-brush flagging approach, which does not distinguish between components actually used in production and those simply present, can result in alerts for unused or non-critical vulnerabilities.
Azul's approach leverages data from Java application production environments to establish whether vulnerable classes in a component are executed, rather than simply existing as part of a packaged file. The company claims this refinement enables the solution to eliminate up to 99% of false positives, translating to a potential 100 to 1,000 times reduction compared to earlier detection methods.
The technical approach
The solution operates by applying a curated knowledge base that maps CVEs to individual Java classes used at runtime. By examining actual code paths executed in live environments, the system can determine whether a flagged vulnerability is relevant and warrants action.One example cited is CVE-2024-1597, which affects specific versions of the PostgreSQL Java Database Connectivity (JDBC) driver.
This high-severity vulnerability, which scores 9.8 out of 10 on the Common Vulnerability Scoring System (CVSS), can only be exploited when the driver is used in a particular non-default configuration. Conventional tools issue alerts if the driver is present in the application package, regardless of how it is used, contributing to unnecessary remediation efforts. Azul's detection mechanism discerns whether any of the 11 susceptible classes out of 470 in the component are used, thereby reducing irrelevant alerts.
Key benefits
According to Azul, the Intelliigence Cloud's Vulnerability Detection capability provides several benefits to enterprises managing extensive Java estates. These include continuous, real-time detection of vulnerabilities in production environments, which helps teams rapidly triage and prioritise critical issues in high-stakes scenarios like the Log4j vulnerability event. The platform retains both real-time and historical data on component and code use, using AI methods to focus forensic investigations on vulnerabilities actively exploited prior to their discovery.
Azul's vulnerability team updates the system's knowledge base with newly identified CVEs, using AI to monitor sources such as the National Vulnerabilities Database (NVD) and other repositories. The runtime data collection works across Oracle JDK as well as any OpenJDK-based Java Virtual Machine (JVM), providing flexibility for organisations using a range of Java distributions, including those from Amazon, Temurin, Microsoft, and Red Hat. Azul states that this data-gathering incurs no impact on production system performance, as it leverages information already generated by the JVM during application execution. "The improved Vulnerability Detection features strengthen the proposition of Azul's Intelligence Cloud analytics SaaS offering as a way to increase DevOps productivity and recover developer capacity by reducing the need for full-time employee time spent wasted on security false positives and inefficient triage," said William Fellows, research director at 451 Research, part of S&P Global Market Intelligence.
Company statement "Our mission is to help enterprises focus their security efforts on what matters - real risk, not noise," said Scott Sellers, co-founder and CEO of Azul. "By eliminating up to 99% of false positives and pinpointing vulnerabilities in Java applications with 100x – 1000x greater accuracy than traditional tools, Azul Intelligence Cloud enables capacity recovery across DevOps and security teams. As a result, teams can dramatically reduce noise, prioritise real risk and accelerate remediation - all with zero impact to performance and without slowing innovation."
Azul's enhancements to its Intelligence Cloud are positioned to address long-standing productivity challenges faced by DevOps teams handling Java application security, particularly the time lost to managing irrelevant or inaccurate alerts.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Java Independence is now a board-level priority - Driving cost savings, cloud efficiency and strategic agility
Java Independence is now a board-level priority - Driving cost savings, cloud efficiency and strategic agility

Techday NZ

time3 days ago

  • Techday NZ

Java Independence is now a board-level priority - Driving cost savings, cloud efficiency and strategic agility

Chances are every time you stream content, buy something online or check your bank balance, you're interacting with Java-based systems. Java powers mission-critical systems across industries. Netflix runs its entire streaming infrastructure on Java-based microservices, processing millions of concurrent viewers. Global payment networks validate credit card transactions in milliseconds across hundreds of countries using Java applications. While the Java community has expanded to over 10 million developers worldwide, enterprises face mounting cost pressures from multiple directions. For the enterprises powering these essential services, 2025 represents a critical decision point: continue paying escalating costs for Oracle Java, potentially impacting profit margins or customer pricing as well as the potential for future price hikes, or seek alternatives. Java independence gives businesses control, choice, and confidence in how they build and run Java applications. Azul's recent 2025 State of Java Survey & Report reveals an enterprise Java ecosystem in transition, driven by mounting cost concerns, market preference for open-source solutions, and ongoing uncertainty around Oracle's licensing policies. This watershed moment stems from Oracle's shift to employee-based pricing in January 2023, which fundamentally disrupted enterprise Java strategy. Oracle's licensing practices have significantly increased Java-related expenditures, with the company generating billions annually from Java licensing and support. This shift isn't just about cost savings, it's about mitigating risk and enhancing agility. Java independence has become a board-level priority in an era where digital transformation drives market leadership. The oracle Java challenge The new Oracle pricing model detaches Java costs from actual usage, creating an unsustainable scenario: a 10,000-employee company running a handful of Java applications pays the same as a similarly sized organisation running thousands of Java-based services. For global businesses, this represents both a financial challenge and a strategic imperative to maintain competitive advantage. Our research reveals that two-thirds of organisations found Oracle's licensing model more expensive than alternatives, and an overwhelming majority reported successful migrations away from Oracle Java. With 25% of companies citing audit risk as a key migration driver, the urgency to transition has become a business priority rather than just an IT concern. The OpenJDK success story The success of OpenJDK adoption has shattered Oracle Java migration concerns. The data tells a compelling story: 84% of companies found the transition easier than expected or as planned, with three-quarters completing migrations within 12 months. This rapid timeline reflects both the maturity of available solutions and the robust support ecosystem around OpenJDK migrations. OpenJDK distributions have emerged as preferred alternatives to Oracle Java. These enterprise-ready solutions match Oracle Java SE's core capabilities while offering enhanced support and performance options. Successful migration hinges on three key components: Organisational momentum - Technical expertise, discovery & inventory tools and project planning assistance from a commercial OpenJDK provider can significantly help secure and maintain executive support, ultimately impacting a successful transition. Comprehensive Java mapping - Identifying all Java deployments across an organisation is essential. With 83% of organisations requiring commercially supported Java in production, this mapping phase is critical. Governance and compliance - Maintaining independence from Oracle Java licensing requires robust governance. Success means partnering with OpenJDK providers offering comprehensive protection, from IP safeguards to indemnification. The immediate financial benefits are substantial — most organisations report a 50-70% reduction in Oracle Java-related costs. Perhaps even more compelling, additional value lies in regaining control over Java technology strategy. Cloud cost optimisation Organisations are grappling with rapidly escalating cloud infrastructure costs, as annual global cloud spending is nearing a trillion dollars and continues to grow at double-digit rates. Our research reveals that 71% of organisations overpay for cloud compute capacity, highlighting an opportunity to reduce costs while improving application performance. Companies that select non-Oracle optimised Java platforms can save 20%+ on cloud computing costs. This is because high-performance Java runtimes deliver more stable Java applications and infrastructure while consuming fewer computing resources, creating compelling advantages beyond just licensing considerations. Powering AI innovation with Java Emerging technology demands amplify the need for change, particularly in AI and cloud computing. Half of the surveyed companies from our State of Java report already build AI functionality using Java — from financial institutions developing fraud detection systems to retailers leveraging machine learning for customer personalisation and inventory management. As computational demands grow, organisations require Java platforms that can deliver both performance and efficiency. These advanced workloads highlight the need for solutions that provide more scalable and stable applications while consuming fewer computing resources, enabling AI initiatives to be deployed successfully without excessive infrastructure investments. Oracle Java independence is not just a technical evolution — it's a strategic imperative that gives organisations the freedom to innovate, control costs, and build their technology future on their own terms.

Agentic AI transforms business operations with enhanced oversight
Agentic AI transforms business operations with enhanced oversight

Techday NZ

time23-06-2025

  • Techday NZ

Agentic AI transforms business operations with enhanced oversight

The integration of agentic artificial intelligence (AI) into business operations is gaining significant momentum across industries, with new research, commentary, and product announcements underscoring both the promise and complexities of these advanced technologies. Matt Johnson, Managing Director for AI & Data at Temus, outlined the evolving landscape of AI agents, noting an industry-wide shift from rudimentary AI interactions towards more advanced, contextually aware systems. "We're witnessing a significant shift in how AI agents are being deployed across industries. The most successful implementations go far beyond basic prompting," Johnson observed. He highlighted the application of sophisticated techniques such as automated reprompting, parameter-efficient fine-tuning, and reinforcement learning, which allow agents to learn from their environments and incorporate expert knowledge. Johnson emphasised that data remains the critical foundation for agentic AI. He noted, "Companies are now realising they need deliberate strategies to acquire and structure this expert knowledge – it's become a competitive differentiator." In sectors such as healthcare and financial services, he asserted, the inclusion of human-in-the-loop workflows is not optional but essential, with the best AI systems augmenting human expertise rather than replacing it. The software development sector, according to Johnson, has provided one of the most compelling success stories, with AI tools such as Claude Code assisting developers by providing contextual suggestions and even autonomously generating code, all while preserving human oversight. This reflects a broader trend, with organisations increasingly viewing AI agents not as autonomous replacements for professionals, but as tools to enhance productivity and decision-making. In the domain of cybersecurity, a new study from Cycode, presented at the RSA Conference 2025, illuminated how agentic AI is reshaping application security practices. The survey found that while 60% of cybersecurity professionals remain in early stages of adoption, those organisations that have embraced agentic AI report notable productivity gains and reduced risks in development and security workflows. Amir Kazemi, Director of Product Marketing at Cycode, observed, "Many interpretations and modalities of 'agent' exist, from simple chatbots to complex workflow automations to true autonomous agents. Our data underscores that educating the market on what agentic AI truly is, why it matters for AppSec, and its tangible value is paramount right now." The Cycode research illustrated growing interest, with almost 50% of surveyed professionals planning to adopt agentic AI in the coming year. Yet, concerns remain about granting AI systems autonomy, with businesses taking a measured approach to integrating these tools. The study identified key opportunities: 44% of professionals believe agentic AI will improve vulnerability management, while 52% see significant value in using AI-driven security checks at the code commit stage. The perceived widening gap between application security and development resources, with some teams managing ratios as high as one security specialist per 1,000 developers, exemplifies the mounting pressure on teams that agentic AI could help alleviate. Financial services are also experiencing AI-driven transformation, as demonstrated by the launch of GTreasury's GSmart AI platform, designed specifically for treasury and finance operations. The platform aims to deliver efficiencies and transparent insights for CFOs and treasury professionals facing complex market and regulatory conditions. GTreasury CEO Renaat Ver Eecke stressed the necessity for AI in finance to prioritise security, compliance, and rapid problem-solving. "GSmart AI... empowers CFOs and treasury teams to confidently take advantage of powerful insights and value without sacrificing compliance or oversight," Ver Eecke stated. The platform provides automated analysis, risk identification, and strategic recommendations, all while ensuring auditability and governance. Mark Johnson, Chief Product Officer at GTreasury, added that GSmart AI is distinguished by its transparency and data sovereignty features, supporting rigorous standards and regulatory requirements. These developments signal that agentic AI, when combined with robust data strategies and clear boundaries for human oversight, is rapidly becoming integral to modern workflows. Whether in software development, cybersecurity, or treasury operations, organisations are increasingly seeking to leverage the unique capabilities of these AI agents to enhance human judgement, streamline complex tasks, and maintain compliance in a rapidly evolving technological landscape.

Azul & Chainguard partner on zero-CVE Java containers
Azul & Chainguard partner on zero-CVE Java containers

Techday NZ

time19-06-2025

  • Techday NZ

Azul & Chainguard partner on zero-CVE Java containers

Azul and Chainguard have announced a partnership focused on strengthening container security for Java workloads through combined commercial Java support and secure container images. The collaboration will see Chainguard create Java container images built from source, incorporating Azul's commercially supported build of OpenJDK from the Azul Platform Core. This approach is designed to allow enterprises to deliver production workloads more efficiently while addressing the complexities of securing the full software stack for Java applications. Complexity in Java security Java remains integral to a wide range of enterprise applications, with growing challenges around ensuring timely access to secure builds. Securing Java workloads requires reliable updates and consistent patching, traditionally necessitating expertise and timely intervention by vendors. Azul aims to fulfil this role by delivering fully supported OpenJDK builds intended as a direct replacement for Oracle Java, enabling organisations to maintain compliance and security while reducing expenditure and freeing development teams from remediation tasks. Chainguard Containers supports customers by securing operating systems and application runtime environments. The combination targets gaps in current protection practices that too often see engineering and security teams handle numerous vulnerability disclosures, deal with inconsistent patching, and attempt to harden containers without slowing developer productivity. For Java workloads, which require both rapid security response and commercial support, these difficulties are particularly pressing. Recent research from NetRise indicates that the average container carries 604 known vulnerabilities in underlying software components. Notably, over 45% of these CVEs are two to ten years old. This accumulation of unaddressed vulnerabilities increases risks for organisations that depend on containerised apps. Findings from Azul's 2025 State of Java Survey & Report further highlight the impact of security issues. According to the report, 33% of respondents stated their DevOps teams spend more than half their time addressing false positives from Java-related vulnerabilities. Additionally, 49% of surveyed companies reported they are still encountering vulnerabilities from Log4j in production environments, nearly three years after the initial disclosure. The need to secure all layers, from operating systems to toolchains, forms a critical part of the software development lifecycle. Hardened, zero-CVE Java containers The partnership between Azul and Chainguard is positioned as a direct response to challenges identified by industry research. The joint offering will deliver zero-CVE containers for Java versions 21 and above, built from Azul's source code and supported commercially through Azul's Java expertise. Customers are expected to benefit from a streamlined way to secure Java application foundations, reducing overall risk exposure and enabling more consistent, reliable deployments. The new container images will be constructed entirely from source and tested in accordance with the Java Compatibility Kit, providing assurance of compatibility and feature parity. Azul's approach to stabilised, security-only Critical Patch Updates gives engineering teams the opportunity to deploy updated Java images more efficiently, minimising manual patching and testing efforts. This is intended to help organisations redirect development resources away from platform maintenance and towards application delivery. "Our customers need solutions that reduce risk and build trust at every layer of their modern software deployment stack," said Dan Lorenc, co-founder and CEO at Chainguard. "Today, we're bringing Chainguard's expertise in building minimal, zero-CVE images and Azul's expertise in Java together to create the most secure, commercial-grade containers for cloud-native workloads." Scott Sellers, co-founder and CEO at Azul, added: "Choosing a hardened container shouldn't mean sacrificing timely security-only updates and commercial support services for your Java runtimes. Today, we're excited to offer enterprises best-in-breed hardened Java containers from Chainguard while leveraging world-class commercial support from Azul." Customers adopting Azul Java container images through Chainguard Containers will have access to commercial Java support within the Azul Platform Core portfolio. This ensures ongoing access to patches and direct assistance for Java runtime issues in critical enterprise environments.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store